Gitlab — веб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.0.8 | 17.0.8 | ||
| 17.0.7 | 17.0.7 | ||
| 17.0.6 | 17.0.6 | ||
| 17.0.5 | 17.0.5 | ||
| 17.0.4 | 17.0.4 | ||
| 17.0.3 | 17.0.3 | ||
| 17.0.2 | 17.0.2 | ||
| 17.0.1 | 17.0.1 | ||
| 17.0.0 | 17.0.0 |
Показывать по
Количество 5 871
CVE-2022-1433
An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previously exploitable XSS vulnerability (CVE-2022-1175) to persist and execute.
CVE-2022-1433
An issue has been discovered in GitLab affecting all versions starting ...
CVE-2022-1428
An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was incorrectly verifying throttling limits for authenticated package requests which resulted in limits not being enforced.
CVE-2022-1428
An issue has been discovered in GitLab affecting all versions before 1 ...
CVE-2022-1426
An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly authenticating a user that had some certain amount of information which allowed an user to authenticate without a personal access token.
CVE-2022-1426
An issue has been discovered in GitLab affecting all versions starting ...
CVE-2022-1406
Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project
CVE-2022-1406
Improper input validation in GitLab CE/EE affecting all versions from ...
CVE-2022-1352
Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1, an endpoint may reveal the issue title to a user who crafted an API call with the ID of the issue from a public project that restricts access to issue only to project members.
CVE-2022-1352
Due to an insecure direct object reference vulnerability in Gitlab EE/ ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2022-1433 An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previously exploitable XSS vulnerability (CVE-2022-1175) to persist and execute. | CVSS3: 2.6 | 1% Низкий | около 4 лет назад | |
CVE-2022-1433 An issue has been discovered in GitLab affecting all versions starting ... | CVSS3: 2.6 | 1% Низкий | около 4 лет назад | |
CVE-2022-1428 An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was incorrectly verifying throttling limits for authenticated package requests which resulted in limits not being enforced. | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
CVE-2022-1428 An issue has been discovered in GitLab affecting all versions before 1 ... | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
CVE-2022-1426 An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly authenticating a user that had some certain amount of information which allowed an user to authenticate without a personal access token. | CVSS3: 2 | 1% Низкий | около 4 лет назад | |
CVE-2022-1426 An issue has been discovered in GitLab affecting all versions starting ... | CVSS3: 2 | 1% Низкий | около 4 лет назад | |
CVE-2022-1406 Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
CVE-2022-1406 Improper input validation in GitLab CE/EE affecting all versions from ... | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
CVE-2022-1352 Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1, an endpoint may reveal the issue title to a user who crafted an API call with the ID of the issue from a public project that restricts access to issue only to project members. | CVSS3: 5.3 | 1% Низкий | около 4 лет назад | |
CVE-2022-1352 Due to an insecure direct object reference vulnerability in Gitlab EE/ ... | CVSS3: 5.3 | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу